Skip to content

Security: sprintthunder-dotcom/agent-brain

SECURITY.md

Security policy

Supported versions

Only the latest tagged release receives security fixes during the alpha phase.

Reporting a vulnerability

Please use GitHub's private vulnerability reporting feature on this repository. Do not open a public issue for a suspected vulnerability and do not include secrets, private knowledge packs, or personal data in a report.

You should receive an acknowledgement within seven days. A fix timeline depends on severity and reproducibility.

Security boundary

Agent Brain is a local filesystem tool. It does not encrypt knowledge, manage credentials, provide a sandbox, or make untrusted content safe. Users remain responsible for filesystem permissions, backups, repository remotes, and the data placed in a brain.

There aren't any published security advisories